VDAI – €110 Fine (Lithuania, 2021)

€110Valstybine duomenu apsaugos inspekcija29 November 2021Lithuania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Lithuania's data protection authority fined CityBee for failing to protect user data, which was exposed online for nearly three years. This case shows the importance of implementing strong security measures to safeguard personal information. Companies should regularly review and update their data protection practices to prevent breaches.

What happened

CityBee's user data was exposed online due to inadequate security measures for nearly three years.

Who was affected

CityBee users whose personal information, including payment details and driving license numbers, was leaked online.

What the authority found

The Lithuanian DPA found CityBee lacked basic security measures, leading to a data breach and a fine.

Why this matters

This case highlights the critical need for robust data security practices. Businesses must ensure they have effective measures in place to protect personal data and avoid breaches that could lead to fines and reputational damage.

GDPR Articles Cited

Art. 32(1)(a) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 83(2)(a) GDPR
Art. 83(2)(b) GDPR
Art. 83(2)(g) GDPR

Entities Involved

VDAI
UAB Prime Leasing
Full Legal Summary
Detailed

The Controller is the operator of a platform for short-term car rental: “CityBee”. It was made aware by another company that provides cyber-security services, that CityBee’s customer data of 110,302 users was published on the website RaidForums.com. The controller notified the DPA, who conducted an investigation. The DPA found out that the personal data was retrieved from an unprotected database backup BACPAC file (DB file), and contained the following: name, address, telephone number, e-mail address, personal identification number, driving license number, type of payment card and the last four digits of the number, the expiration date of the payment card, and the user identifier (token) in Braintree (software for online payments). This DB file was created on 27 February 2018, and access to the file was suspended on 16 February 2021. Hence, the DPA concluded that the personal data breach existed for this entire period. The DPA found that a number of organisational and technical security measures were missing: there was no competent person responsible for security and risk management, no logs were kept of access and changes to the DB files, the DB file was stored unencrypted, the passwords in the DB file had a weak encryption (SHA-1) and easy to retrieve by persons with technical knowledge, and users could make passwords that did not comply with the requirements as set out in the company’s IT security policy. Lastly, the controller did not assess and manage the risks associated with the loss of the DB file, since it was not even aware of the existence of this DB in the first place (!). The DPA considered the lack of organizational and technical measures and held that properly using basic security measures, such as authenticated access to the DB file only for staff members, encrypting the DB file and entrusting only authorised staff members with the encryption key, or proper monitoring of information resources, would have ensured confidentiality of the personal da

Related Enforcement Actions (0)

No other enforcement actions found for VDAI in LT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

29 November 2021

Authority

Valstybine duomenu apsaugos inspekcija

Fine Amount

€110

GDPRhub ID

gdprhub-4395

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. VDAI - Lithuania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: